Vulnerability Details CVE-2020-11729
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-11729
-
cpe:2.3:a:davical:andrew's_web_libraries:-
-
cpe:2.3:a:davical:andrew's_web_libraries:0.54
-
cpe:2.3:a:davical:andrew's_web_libraries:0.55
-
cpe:2.3:a:davical:andrew's_web_libraries:0.55-1
-
cpe:2.3:a:davical:andrew's_web_libraries:0.56
-
cpe:2.3:a:davical:andrew's_web_libraries:0.56-2
-
cpe:2.3:a:davical:andrew's_web_libraries:0.57
-
cpe:2.3:a:davical:andrew's_web_libraries:0.57-1
-
cpe:2.3:a:davical:andrew's_web_libraries:0.58
-
cpe:2.3:a:davical:andrew's_web_libraries:0.59
-
cpe:2.3:a:davical:andrew's_web_libraries:0.60
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:9.0